Description
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.
Remediation
References
https://github.com/ming-soft/MCMS
https://github.com/ming-soft/MCMS/issues/42
Related Vulnerabilities
CVE-2017-16163 Vulnerability in npm package dylmomo
CVE-2020-7708 Vulnerability in npm package @irrelon/path
CVE-2021-43571 Vulnerability in npm package starkbank-ecdsa
CVE-2018-16469 Vulnerability in maven package org.webjars.npm:merge
CVE-2021-43138 Vulnerability in maven package org.webjars.bower:async